Thomas Byrne
Security Consultant II
More By Thomas Byrne
Cloud Pentesting
Azure VM Command Execution using Third-Party Extensions – Salt Minion
July 27, 2026
In part two of our series, learn how attackers can leverage this legitimate tool to achieve undetected, arbitrary code execution as root, and explore the key detection methods you need to protect your Linux and Windows environments.
Learn More
Cloud Pentesting
Azure VM Command Execution using Third-Party Extensions – Chef
July 21, 2026
Discover how a privileged principal in Azure can abuse third-party extensions like Chef to achieve arbitrary command execution on target VMs by deploying malicious cookbooks to extract Managed Identity tokens.
Learn More
Cloud Pentesting
Bypassing Microsoft Entra Conditional Access Policies via Nested App Authentication
June 22, 2026
Discover how attackers bypassed Microsoft Entra Conditional Access Policies using Nested App Authentication (NAA) flows in this technical vulnerability breakdown.
Learn More